mirror of
https://github.com/rancher/rancher-docs.git
synced 2026-09-29 06:29:34 +00:00
updates to benchmark-2.3, hardening-2.3.5
This commit is contained in:
@@ -34,7 +34,6 @@ When performing the tests, you will need access to the Docker command line on th
|
|||||||
The following scored controls do not currently pass, and Rancher Labs is working towards addressing these through future enhancements to the product.
|
The following scored controls do not currently pass, and Rancher Labs is working towards addressing these through future enhancements to the product.
|
||||||
|
|
||||||
- 1.1.21 - Ensure that the `--kubelet-certificate-authority` argument is set as appropriate (Scored)
|
- 1.1.21 - Ensure that the `--kubelet-certificate-authority` argument is set as appropriate (Scored)
|
||||||
- 2.1.8 - Ensure that the `--hostname-override` argument is not set (Scored)
|
|
||||||
|
|
||||||
### Controls
|
### Controls
|
||||||
|
|
||||||
@@ -148,7 +147,7 @@ docker inspect kube-apiserver | jq -e '.[0].Args[] | match("--profiling=false").
|
|||||||
|
|
||||||
**Note:** This deprecated flag was removed in 1.14, so it cannot be set.
|
**Note:** This deprecated flag was removed in 1.14, so it cannot be set.
|
||||||
|
|
||||||
**Result:** Pass
|
**Result:** Not Applicable
|
||||||
|
|
||||||
#### 1.1.10 - Ensure that the admission control plugin `AlwaysAdmit` is not set (Scored)
|
#### 1.1.10 - Ensure that the admission control plugin `AlwaysAdmit` is not set (Scored)
|
||||||
|
|
||||||
@@ -756,17 +755,9 @@ docker inspect kube-controller-manager | jq -e '.[0].Args[] | match("--root-ca-f
|
|||||||
|
|
||||||
**Notes**
|
**Notes**
|
||||||
|
|
||||||
RKE does not yet support certificate rotation. This feature is due for the 0.1.12 release of RKE.
|
RKE handles certificate rotation through an external process.
|
||||||
|
|
||||||
**Audit**
|
**Result:** Not Applicable
|
||||||
|
|
||||||
``` bash
|
|
||||||
docker inspect kube-controller-manager | jq -e '.[0].Args[] | match("--feature-gates=.*(RotateKubeletServerCertificate=true).*").captures[].string'
|
|
||||||
```
|
|
||||||
|
|
||||||
**Returned Value:** `RotateKubeletServerCertificate=true`
|
|
||||||
|
|
||||||
**Result:** Pass
|
|
||||||
|
|
||||||
#### 1.3.7 - Ensure that the `--address` argument is set to 127.0.0.1 (Scored)
|
#### 1.3.7 - Ensure that the `--address` argument is set to 127.0.0.1 (Scored)
|
||||||
|
|
||||||
@@ -1509,15 +1500,7 @@ docker inspect kubelet | jq -e '.[0].Args[] | match("--make-iptables-util-chains
|
|||||||
**Notes**
|
**Notes**
|
||||||
This is used by most cloud providers. Not setting this is not practical in most cases.
|
This is used by most cloud providers. Not setting this is not practical in most cases.
|
||||||
|
|
||||||
**Audit**
|
**Result:** Not Applicable
|
||||||
|
|
||||||
``` bash
|
|
||||||
docker inspect kubelet | jq -e '.[0].Args[] | match("--hostname-override=.*").string'
|
|
||||||
```
|
|
||||||
|
|
||||||
**Returned Value:** `--hostname-override=<ipv4 address>`
|
|
||||||
|
|
||||||
**Result:** Fail
|
|
||||||
|
|
||||||
#### 2.1.9 - Ensure that the `--event-qps` argument is set to `0` (Scored)
|
#### 2.1.9 - Ensure that the `--event-qps` argument is set to `0` (Scored)
|
||||||
|
|
||||||
@@ -1581,19 +1564,15 @@ docker inspect kubelet | jq -e '.[0].Args[] | match("--rotate-certificates=true"
|
|||||||
|
|
||||||
**Returned Value:** `null`
|
**Returned Value:** `null`
|
||||||
|
|
||||||
**Result:** Pass (Not Applicable)
|
**Result:** Not Applicable
|
||||||
|
|
||||||
#### 2.1.13 - Ensure that the `RotateKubeletServerCertificate` argument is set to `true` (Scored)
|
#### 2.1.13 - Ensure that the `RotateKubeletServerCertificate` argument is set to `true` (Scored)
|
||||||
|
|
||||||
**Audit**
|
**Notes**
|
||||||
|
|
||||||
``` bash
|
RKE handles certificate rotation through an external process.
|
||||||
docker inspect kubelet | jq -e '.[0].Args[] | match("--feature-gates=.*(RotateKubeletServerCertificate=true).*").captures[].string'
|
|
||||||
```
|
|
||||||
|
|
||||||
**Returned Value:** `RotateKubeletServerCertificate=true`
|
**Result:** Not Applicable
|
||||||
|
|
||||||
**Result:** Pass
|
|
||||||
|
|
||||||
#### 2.1.14 - Ensure that the kubelet only makes use of strong cryptographic ciphers (Not Scored)
|
#### 2.1.14 - Ensure that the kubelet only makes use of strong cryptographic ciphers (Not Scored)
|
||||||
|
|
||||||
|
|||||||
@@ -179,7 +179,6 @@ services:
|
|||||||
infra_container_image: ""
|
infra_container_image: ""
|
||||||
cluster_dns_server: ""
|
cluster_dns_server: ""
|
||||||
fail_swap_on: false
|
fail_swap_on: false
|
||||||
generate_serving_certificate: true
|
|
||||||
kubeproxy:
|
kubeproxy:
|
||||||
image: ""
|
image: ""
|
||||||
extra_args: {}
|
extra_args: {}
|
||||||
|
|||||||
Reference in New Issue
Block a user